World Models · public research draft

Ownership / Stewardship

Provide the reusable control facet that can be attached to any meta-object so that an agent can determine who holds it, who may lawfully act for the holder, under what basis and constraints, and how control moved or will move — independently of what the object itself is.

AI YAMLAGENTS.mdResearch evidence
Research draft. The Claude + Grok synthesis is public for review and use with caution. It passed structural validation but is not yet a canonical Vercy release because the source and coverage holds below remain open.
Catalogue IDWM-XCT-001
Version0.3.0-research.1
Previous version-
Typemixin
ValidationPassed
Synthesis digestsha256:b7e519210f7cc00c…
28Sources
6Bundles
15Layers
31Findings
120Questions
28Artifacts
Format-independent logical structure

Bundles → Layers → Findings → Questions + Artifacts

control-anchorControllability and Anchoring2 layers

What makes a meta-object subject to a control record at all, how that record is identified and versioned, which modality of control is asserted, and on what basis.

object-bindingObject Binding and Record Identity2 findings

The reference from a control assertion to the meta-object it governs, the controllability of that object, and the identity and version discipline of the assertion itself.

controllable-object-anchor

Controllable object anchor

A control record binds to exactly one referenced meta-object. The reference must resolve, and the object must be of a kind that can bear control: MLETR and UCC Article 12 both gate control on the record being susceptible to exclusive control, and CID makes control turn on the ability to update a canonical resource. Objects that are pure abstractions, aggregates without a canonical instance, or copies without a single authoritative instance are not controllable and must be flagged rather than silently given an owner.

Questions
  1. Which single meta-object does this control assertion govern, and does that reference resolve to a canonical instance rather than a copy or a class?identity
    Expected answer
    • object reference (identifier of the governed meta-object)
    • object kind / classifier
    • canonical-instance flag
    • resolution status of the reference
  2. Is the object susceptible to exclusive control, or does it exist as indefinitely reproducible copies with no authoritative instance?classification
    Expected answer
    • controllability class (exclusively-controllable | jointly-controllable | non-exclusive | non-controllable)
    • authoritative-instance mechanism
    • justification text
  3. Does control extend to the whole object or only to a defined part, aspect or bundle of it?composition
    Expected answer
    • control extent (whole | part | aspect)
    • part descriptor or aspect qualifier
    • excluded aspects
  4. If the object is an aggregate, is control asserted over the aggregate, over each member, or over both with different holders?relationship
    Expected answer
    • aggregation handling rule
    • member control records referenced
    • conflict-with-member flag
Artifacts
  • Control anchor recordThe register entry that makes a meta-object controllable: object reference, controllability class, extent and the registration basis that admitted it.
control-record-identity-versioning

Control record identity and versioning

Identity and version discipline for the assertion itself. LADM derives its core classes from a versioned object with an object identifier, so that a superseded holding remains addressable rather than being overwritten. A control record must therefore be immutably identified, carry a version lineage, and never be identified by the date on which it took effect.

Questions
  1. Which identifier authority governs this control record: an authoritative master register, a governed global IRI, or a locally minted UUID/ULID?identity
    Expected answer
    • record identifier
    • identifier scheme and issuing authority
    • identity tier (master | governed-global | local-surrogate)
  2. Which prior version does this record supersede, and is the superseded version still resolvable?provenance
    Expected answer
    • supersedes reference
    • version number or sequence
    • superseded-record retrievability flag
  3. Does this new version correct an error in the prior record or record a real-world change of control?classification
    Expected answer
    • revision type (correction | real-world-change | reclassification)
    • correction reason code
    • corrected fields
control-natureModality and Basis of Control3 findings

Which kind of control is being asserted and what makes the assertion admissible.

control-modality-classification

Control modality classification

'Ownership' is not a single relation. The sources support at least five distinguishable modalities: legal title or tenure right (LADM LA_Right), beneficial interest (AMLR beneficial owner), custody or possession-equivalent control (MLETR, UCC-12), administrative controllership and accountability (GDPR controller; NIST information owner; ISO/IEC 27002 asset owner), and de-facto technical control (CID controller). These have different transfer rules, different evidence and different consequences; the EU Data Act explicitly refuses to convert a data holder's position into a new right. The modality must therefore be an explicit, non-defaulted field.

Questions
  1. Which control modality does this record assert — legal title, beneficial interest, custody, administrative controllership, or de-facto technical control?classification
    Expected answer
    • control modality code
    • modality definition source reference
    • modality-specific qualifiers
  2. Do several modalities over this object coexist with different parties, and are they recorded as separate assertions rather than merged?relationship
    Expected answer
    • coexisting control record references
    • modality per record
    • separation-maintained flag
  3. Does the asserted modality carry a transferable right, or only accountability without any proprietary claim?authority
    Expected answer
    • transferability (transferable | non-transferable | transferable-with-consent)
    • confers-proprietary-right boolean
    • basis for the non-proprietary reading
  4. If the modality is unknown, is the record held as unclassified rather than defaulted to legal title?exception
    Expected answer
    • modality-unknown flag
    • provisional handling rule
    • escalation route
Artifacts
  • Control modality vocabularyThe governed code list of control modalities with definitions, source alignment and transfer semantics for each.
basis-of-control

Basis and admissibility of control

Every control assertion must name the ground that created it and the source document evidencing that ground — LADM binds each class to a source, and MLETR conditions control on a reliable method being used. The basis distinguishes a first registration from a derivative acquisition, and records whether the recording itself is constitutive of the right or merely declaratory of it, which changes what an agent may infer from a silent register.

Questions
  1. What legal, contractual, customary or administrative ground creates this control, and is it original or derivative?provenance
    Expected answer
    • basis code (statute | contract | customary | administrative act | first appropriation | court order | technical control)
    • acquisition type (original | derivative)
    • citation of the instrument or rule
  2. Which source documents evidence the basis, and what is their type and reliability?evidence
    Expected answer
    • source document references
    • source type (administrative | private instrument | attestation | observation)
    • reliability assessment
  3. Is recording in this register constitutive of the control, or merely declaratory of a control that exists independently?authority
    Expected answer
    • recording effect (constitutive | declaratory | evidentiary-only)
    • governing register reference
    • consequence of non-recording
  4. If the basis is customary, communal or informal, is it recorded as legitimate rather than as an absence of tenure?exception
    Expected answer
    • tenure form (public | private | communal | indigenous | customary | informal)
    • recognition status in the operating jurisdiction
    • VGGT-alignment note
Artifacts
  • Basis source dossierThe set of instruments, attestations or administrative acts cited as the ground of a control assertion, with type, issuer and integrity data for each.
governing-law-and-situs

Applicable law and situs

HCCH Articles 6–8: a trust is governed by the law chosen by the settlor or, failing that, the law of closest connection, ascertained especially from place of administration, situs of assets, residence of the trustee, and objects of the trust. Article 9 allows a severable aspect, particularly administration, to be governed by a different law. Article 15 lists mandatory forum rules that cannot be derogated from by voluntary act. DCMI coverage and Jurisdiction describe spatial applicability or the jurisdiction under which a resource is relevant. FAO VGGT is implemented through national strategies and legislation; it is not self-executing title. Lex rei sitae for tangible objects, lex societatis for legal persons, and chosen trust law may therefore diverge for one meta-object; the mixin records each pointer rather than picking a single world law.

Questions
  1. Which law governs this holding or trust, was it chosen or selected by closest connection, and what is the situs of the assets or administration?authority
    Expected answer
    • governing-law: law
    • choice-mode: mode
    • situs: situs
  2. Are administration or other severable aspects governed by a different law, and which mappings apply?composition
    Expected answer
    • severable-aspects: aspect-law pairs
  3. Which HCCH Article 15 mandatory categories (minors, marriage, succession, security interests, insolvency, good faith) override the chosen law for this object?exception
    Expected answer
    • mandatory-forum-rules: categories hit
    • effect: how recognition or transfer is constrained
  4. Through which national policy or statute, if any, are VGGT tenure principles applied to this object?interoperability
    Expected answer
    • national-instrument: instrument or none
    • jurisdiction-of-relevance: jurisdiction
Artifacts
  • Governing law recordRecord of chosen or closest-connection law, situs, severable aspects and mandatory forum rules affecting a holding or trust.
holdingHolding, Shares and Encumbrances3 layers

Who holds the object, in what proportions and under which co-holder decision rules, what encumbers the holding, and what duties the holding carries.

holder-identificationHolder Identification2 findings

Binding parties to the object in holder roles, including group and collective holders, and separating the party of record from the party who actually benefits.

holder-party-binding

Holder party binding

The holder side is a set of party references with declared roles, resolved against the person and organization models. LADM distinguishes an individual party from a group party with members, which is what allows a community, a household, a partnership or an unincorporated body to hold without being forced into a legal-person shape. The binding carries a role and a validity interval, not the party's attributes.

Questions
  1. Which parties are bound as holders of this object, and in which role does each stand?ownership
    Expected answer
    • party references
    • holder role per party (sole | co-holder | nominee | trustee | representative)
    • validity interval per binding
  2. Is the holder an individual party or a group party, and if a group, is its membership enumerated or defined by rule?composition
    Expected answer
    • party form (individual | group | collective | unincorporated body)
    • membership enumeration or membership rule
    • membership-as-of timestamp
  3. Does every party reference resolve in the person or organization model, and what happens when one does not?validation
    Expected answer
    • resolution status per reference
    • unresolved-party handling rule
    • provisional-party placeholder identifier
  4. If no holder can currently be identified, is the object recorded as holder-unknown with a search obligation rather than left with a stale holder?exception
    Expected answer
    • holder-unknown flag
    • diligent-search status and date
    • interim custodian reference
Artifacts
  • Current holder extractA minimal third-party-readable statement of the present holder(s) of a named object, deliberately omitting history, shares, mandates and capacity arrangements.
shares-and-coholdingShares and Co-Holding1 findings

How a single holding is partitioned among co-holders and how co-holders decide.

fractional-and-joint-holding

Fractional and joint holding

LADM's generic conceptual model provides an explicit Fraction class precisely because shares must be exact and must sum correctly. Beyond the arithmetic, co-holding needs a decision rule: whether a disposal requires unanimity, a majority by share, or any single holder acting alone. GDPR's joint-controller arrangement shows the same need — joint responsibility is meaningless unless the allocation between the parties is determined and transparent.

Questions
  1. What exact fraction does each co-holder hold, and do the fractions sum to unity for the recorded extent?measurement
    Expected answer
    • fraction numerator and denominator per holder
    • sum validation result
    • unallocated residue if any
  2. Is the co-holding joint (undivided, with survivorship) or several (divided into distinct shares)?classification
    Expected answer
    • co-holding form (joint | several | joint-and-several | in-common)
    • survivorship rule
    • severability conditions
  3. What threshold of co-holders is required to dispose of, encumber or delegate the object?constraint
    Expected answer
    • decision rule per act type
    • threshold expression
    • deadlock resolution route
  4. Where responsibility rather than value is shared, how is it allocated between the parties and where is that allocation published?authority
    Expected answer
    • responsibility allocation statement reference
    • allocated duties per party
    • point of contact for affected parties
Artifacts
  • Share scheduleA dated schedule of co-holders, exact fractions, co-holding form and decision thresholds, superseded as a whole on each restructuring.
qualificationsEncumbrances and Holder Duties2 findings

Restrictions and responsibilities that qualify a holding without moving it.

restrictions-and-encumbrances

Restrictions and encumbrances

LADM treats restrictions as first-class alongside rights, and UCC Article 12 lets a secured party perfect an interest by taking control of a controllable electronic record — meaning an encumbrance can itself be a control position held by someone other than the holder. Encumbrances must therefore be recorded with their beneficiary, their priority rank and their effect on transferability, not as free text.

Questions
  1. What restrictions, security interests or charges currently qualify this holding, and who benefits from each?constraint
    Expected answer
    • encumbrance type
    • beneficiary party reference
    • secured amount or scope
    • instrument reference
  2. In what priority order do competing encumbrances rank, and on what basis is that rank determined?relationship
    Expected answer
    • priority rank
    • priority basis (registration order | control | statutory)
    • subordination agreements
  3. Does this encumbrance block, condition or merely notify a transfer of control?constraint
    Expected answer
    • transfer effect (blocking | consent-required | notice-only)
    • consenting party reference
    • release condition
  4. What event releases the encumbrance, and is release recorded as a separate assertion?lifecycle
    Expected answer
    • release trigger
    • release instrument reference
    • release timestamp
Artifacts
  • Encumbrance certificateA point-in-time statement of all subsisting encumbrances on an object with priority ranks, issued to counterparties before a transfer.
holder-responsibilities

Holder responsibilities

Control carries obligations, not only powers. LADM places responsibilities beside rights and restrictions; NIST defines the information owner by responsibility for controls across the whole information lifecycle; ISO/IEC 27002 control 5.9 requires a named owner accountable for the asset and timely reassignment on transfer or role change; ODRL models the same shape as a Duty. Recording duties makes an unattended or orphaned object detectable.

Questions
  1. What responsibilities attach to holding this object, and are they duties of the holder, of a steward, or of both?requirement
    Expected answer
    • duty descriptions
    • duty bearer role
    • duty source (statute | policy | contract | control framework)
  2. How is discharge of each responsibility evidenced, and what is the consequence of non-discharge?evidence
    Expected answer
    • discharge evidence reference
    • last discharge timestamp
    • non-discharge consequence
  3. When the named owner leaves a role or the object is transferred, what triggers timely reassignment of the responsibility?process
    Expected answer
    • reassignment trigger event
    • target time to reassign
    • current assignment status
  4. Which objects currently carry responsibilities with no assigned bearer?quality
    Expected answer
    • unassigned-duty count per object
    • age of the gap
    • escalation owner
Artifacts
  • Accountability registerThe cross-object inventory of controlled objects with their accountable owner or steward, duty set and reassignment status.
stewardship-delegationStewardship, Delegation and Capacity3 layers

Control exercised by someone who is not the holder: appointed stewards and custodians, scoped delegated authority, and arrangements where the holder cannot act unaided.

steward-appointmentSteward and Custodian Appointment2 findings

Appointment of a party to operate or safeguard an object on the holder's behalf without beneficial holding.

steward-custodian-appointment

Steward and custodian appointment

A steward operates an object under the holder's instruction and gains no beneficial position, as GDPR's processor acts only on behalf of the controller and dcterms:provenance treats custody changes as significant to authenticity in their own right. The appointment must carry its instruction limits, duty set, term and accountability route, so that a steward acting beyond instruction is detectable and can be reclassified as an independent controller.

Questions
  1. Which party is appointed steward or custodian, over which extent of the object, and by whose authority?authority
    Expected answer
    • steward party reference
    • appointing party reference
    • appointment instrument reference
    • covered extent
  2. What may the steward do only on instruction, and what may it decide independently?constraint
    Expected answer
    • instructed acts
    • discretionary acts
    • prohibited acts
  3. What happens if a steward determines purposes and means of its own, rather than acting on instruction?exception
    Expected answer
    • role reclassification rule
    • detection signal
    • notification obligations
  4. For what term does the appointment run, and what must the steward do on termination — return, transfer or destroy?lifecycle
    Expected answer
    • term start and end (RFC 3339)
    • termination trigger
    • end-of-term disposition obligation
Artifacts
  • Steward appointment instrumentThe instrument appointing a steward or custodian, stating duties, instruction limits, term, sub-contracting rules and end-of-term disposition.
trust-arrangement-and-separate-fund

Trust parties and separate fund

HCCH Trusts Convention Article 2 defines a trust as a relationship created inter vivos or on death by a settlor when assets are placed under the control of a trustee for a beneficiary or a specified purpose. Characteristics: the assets are a separate fund and not part of the trustee's own estate; title stands in the trustee or another on the trustee's behalf; the trustee has the power and the duty, in respect of which the trustee is accountable, to manage, employ or dispose of the assets. Reservation of settlor powers, and the trustee also being a beneficiary, are not necessarily inconsistent with a trust. Article 11 requires that personal creditors of the trustee have no recourse against trust assets and that those assets do not fall into the trustee's insolvency, matrimonial property or death estate. The Convention applies only to voluntarily created trusts evidenced in writing (Article 3) and does not bind States to recognise trusts whose significant elements connect to non-trust States (Article 13).

Questions
  1. Who is the settlor, who are the trustees, who are the beneficiaries or what is the purpose, and is the trustee also a beneficiary?relationship
    Expected answer
    • settlor-party-id: settlor
    • trustee-party-ids: trustees
    • beneficiary-party-ids: beneficiaries
    • purpose: purpose if any
    • trustee-is-beneficiary: overlap flag
  2. Do the assets constitute a separate fund that is excluded from the trustee's personal, insolvency, matrimonial and death estates, and where is that ring-fence recorded?constraint
    Expected answer
    • separate-fund-flag: segregation
    • ring-fence-status: how Article 11 effects are recorded
    • asset-title-standing: in trustee name or nominee for trustee
  3. Which law governs the trust, was it chosen by the settlor or selected by closest connection, and is recognition refused under Article 13?authority
    Expected answer
    • governing-law: law identifier
    • choice-mode: express, implied, closest-connection
    • recognition-status: recognition outcome
  4. What powers and duties does the trustee have to manage, employ or dispose, to delegate, to create security interests, and to account, and how is the trustee removed?requirement
    Expected answer
    • power-list: Article 8 powers in force
    • account-route: duty to account
    • removal-rule: appointment and removal rule
Artifacts
  • Trust instrumentWritten instrument creating or evidencing the trust, including chosen law and trustee powers.
delegated-authorityDelegated Authority2 findings

Scoped, revocable grants of specific control powers, their verification, and the attribution of acts performed under them.

delegation-mandate-scope

Delegation mandate scope

A mandate grants named powers, never more than the granting position holds. CID's capabilityDelegation and DID's notion of a delegate express the mechanism; ODRL's assigner/assignee and constraint model express the scoping; PROV records that the delegating agent retains some responsibility. Sub-delegation must be explicit, because silent sub-delegation is the main way scope escapes its origin.

Questions
  1. Which specific powers are delegated, over which object extent, and under what constraints of time, place, purpose or value?authority
    Expected answer
    • delegated power list
    • object extent
    • constraint expressions (temporal, purpose, monetary, spatial)
  2. From which control position does the mandate flow, and is every delegated power contained within that position?relationship
    Expected answer
    • issuing control record reference
    • containment check result
    • excess-power findings
  3. May the delegate sub-delegate, to whom, and does the chain depth have a hard limit?composition
    Expected answer
    • sub-delegation permitted flag
    • permitted sub-delegate classes
    • maximum chain depth
    • current chain
  4. When the delegate acts, is the act attributed to the delegate representing the holder, or does the delegate become indistinguishable from the holder?provenance
    Expected answer
    • attribution mode (representation | impersonation)
    • acting party identifier
    • on-behalf-of party identifier
Artifacts
  • Delegation mandateThe machine-verifiable grant of scoped control powers from a holder to a delegate, including constraints, expiry, sub-delegation rule and revocation endpoint.
mandate-verification-revocation

Mandate verification and revocation

A mandate is only useful if a counterparty can check, at the moment of reliance, that it exists, is in scope and is unrevoked. Revocation is never instantaneous in a distributed setting, so the model must record the revocation timestamp, the publication timestamp and the reliance rule that governs acts falling in the gap. RFC 8693's may_act shows the same pattern: authorization to become an actor is a checkable statement, not an ambient property.

Questions
  1. At the moment of reliance, what evidence shows the mandate was live, in scope and unrevoked?validation
    Expected answer
    • verification timestamp (RFC 3339)
    • status source consulted
    • scope match result
    • verifier identity
  2. When was the mandate revoked, when was that revocation published, and how large was the gap?temporal
    Expected answer
    • revocation effective timestamp
    • revocation publication timestamp
    • propagation gap duration
  3. Are acts performed in good faith during the revocation propagation gap treated as valid, void, or voidable?exception
    Expected answer
    • reliance rule
    • good-faith test criteria
    • remediation route for affected counterparties
  4. How can a mandate be verified when the issuing register is unreachable, and what assurance is lost?interoperability
    Expected answer
    • offline verification method
    • maximum acceptable staleness
    • degraded-assurance marker
Artifacts
  • Mandate verification recordThe evidence a relying party retains showing what it checked, when, against which status source, and with what outcome.
capacity-and-collectiveCapacity and Collective Authority2 findings

Arrangements where the holder cannot act unaided, and holdings whose authority is collective rather than individual.

capacity-support-arrangements

Capacity and decision-support arrangements

CRPD Article 12 recognises legal capacity on an equal basis and requires access to support in exercising it; where any measure relating to legal capacity is used it must respect the person's rights, will and preferences, be free of conflict of interest and undue influence, be proportional and tailored, apply for the shortest time possible, and be subject to regular review by a competent, independent and impartial authority. A control model must therefore default to supported decision-making and treat full substitution as a bounded, reviewable exception carrying an expiry — not as a permanent 'guardian' field.

Questions
  1. Is this arrangement supported decision-making, partially substituted, or fully substituted, and why was the least restrictive option not sufficient?classification
    Expected answer
    • arrangement mode
    • least-restrictive-alternative justification
    • scope of substituted acts
  2. Which safeguards are recorded: conflict-of-interest screening, proportionality, tailoring, and the shortest-time limit?requirement
    Expected answer
    • conflict-of-interest declaration
    • proportionality assessment
    • arrangement end date (RFC 3339)
    • tailoring notes
  3. Which competent, independent and impartial authority reviews the arrangement, and when is the next review due?authority
    Expected answer
    • reviewing authority reference
    • last review date
    • next review due date
    • review outcome
  4. How are the person's own will and preferences recorded and given effect within the arrangement?requirement
    Expected answer
    • expressed will and preference record reference
    • communication support used
    • deviation justification where preferences were not followed
Artifacts
  • Capacity arrangement recordThe record of a support or substitution arrangement over a holding, with mode, scope, safeguards, expiry, review authority and review history. Highly sensitive; disclosed only to parties with a demonstrated need.
collective-authority-to-control

Collective and community authority to control

Some holdings vest in a people, community or governing body rather than in an individual or a corporate person. CARE asserts that Indigenous Peoples' rights and interests in Indigenous data must be recognised and their authority to control empowered, and that Indigenous data governance comprises both stewardship and the processes implementing that control. VGGT requires respect for communal, indigenous, customary and informal tenure. This is a distinct authority shape: consent is given by a governance process, is often non-transferable, and may persist even where a third party physically holds the object.

Questions
  1. Which community or governing body holds authority to control, and by what internal process is a decision reached?authority
    Expected answer
    • governing body reference
    • decision process description
    • quorum or consent standard
    • authorised representative(s)
  2. Where a third party physically holds the object, does collective authority persist independently of that custody?relationship
    Expected answer
    • persisting-authority flag
    • custodian reference
    • obligations of the custodian to the authority holder
  3. Is the collective authority alienable at all, and if not, how is that non-transferability enforced against downstream recipients?constraint
    Expected answer
    • alienability code
    • downstream binding mechanism
    • attached use conditions
  4. What return or benefit flows back to the community from uses of the object, and how is it reported?requirement
    Expected answer
    • benefit-sharing terms
    • reporting obligation and cadence
    • responsible party
Artifacts
  • Collective authority statementA community-issued statement of who holds authority to control an object, the consent process, attached use conditions and benefit-sharing terms, travelling with the object downstream.
transferTransfer, Succession and Exclusivity2 layers

How control originates, moves, lapses and ends, and what prevents two parties from claiming it at once.

conveyanceConveyance3 findings

Voluntary transfer of control between parties, its instrument, its exclusivity guarantee and its validity.

transfer-instrument-execution

Transfer instrument and execution

A transfer is an event with an instrument, named parties, conditions precedent and at least three distinct times: when the instrument was executed, when the transfer took legal or operational effect, and when the register recorded it. Conflating them makes backdating undetectable and makes it impossible to answer who held the object at a past instant.

Questions
  1. Which parties transfer and receive control, in which modality, and over which extent of the object?event
    Expected answer
    • transferor references
    • transferee references
    • transferred modality
    • transferred extent or fraction
  2. When was the instrument executed, when did the transfer take effect, and when was it recorded?temporal
    Expected answer
    • execution timestamp (RFC 3339)
    • effective timestamp (RFC 3339)
    • recorded timestamp (RFC 3339)
    • backdating flag
  3. What conditions precedent must be satisfied before the transfer takes effect, and which remain outstanding?constraint
    Expected answer
    • condition list with satisfaction status
    • consent requirements (encumbrance holders, co-holders, authorities)
    • outstanding condition count
  4. Is the transfer for consideration, gratuitous, or an administrative reassignment, and is that fact relevant to its reversibility?classification
    Expected answer
    • transfer character (for-consideration | gratuitous | administrative | involuntary)
    • reversibility rule
    • reference to the settlement record held elsewhere
Artifacts
  • Transfer instrumentThe executed instrument conveying control, naming parties, modality, extent, conditions precedent and execution particulars.
exclusivity-and-double-transfer

Exclusivity and double-transfer prevention

MLETR requires a reliable method establishing exclusive control by a single person and identifying that person; UCC Article 12 defines control as including the exclusive power to prevent others from availing themselves of the benefit and the exclusive power to transfer. Operationally this means the register must guarantee a single authoritative position per object-and-modality at every instant, detect and reject concurrent dispositions, and be able to prove which of two competing transfers came first.

Questions
  1. What reliable method establishes that exactly one party is in control of this object in this modality at this instant?validation
    Expected answer
    • exclusivity mechanism description
    • single-authoritative-instance guarantee
    • reliability assessment and its assessor
  2. How are two concurrent transfer attempts on the same object detected, ordered and resolved?process
    Expected answer
    • concurrency control mechanism
    • ordering key and its source of truth
    • rejection response and notification
  3. If the register forks or is replicated, which replica is authoritative and how is a divergent branch reconciled?exception
    Expected answer
    • authoritative replica designation
    • divergence detection signal
    • reconciliation procedure and its authority
  4. How is a non-authoritative copy of the object or its instrument marked so it cannot be presented as the controlled instance?security
    Expected answer
    • copy marking method
    • authoritative-instance indicator
    • verification instruction for counterparties
transfer-validity-and-acquisition

Transfer validity and good-faith acquisition

Not every executed transfer is a valid one. UCC Article 12's qualifying-purchaser rules show that a system may protect a good-faith acquirer even against a defect upstream, which means a control record must be able to represent a transfer that is void, voidable, or valid-but-defective, and must record whether downstream acquirers are protected. Silently deleting a bad transfer destroys the very evidence needed to resolve the consequences.

Questions
  1. Is this transfer valid, void, voidable or subject to a pending challenge, and on what ground?state
    Expected answer
    • validity status
    • defect ground
    • challenging party reference
    • challenge status
  2. If a transfer is set aside, which downstream transfers and encumbrances are affected, and which acquirers are protected?relationship
    Expected answer
    • affected downstream record references
    • protection rule applied
    • protected acquirer determinations
  3. How is an invalid transfer corrected — by reversal entry, annulment or restitution — and is the original entry preserved?process
    Expected answer
    • correction mechanism
    • reversal record reference
    • original-entry preservation flag
Artifacts
  • Annulment or reversal entryA compensating register entry recording that a prior transfer is void, voided or reversed, citing the authority for that determination and preserving the original entry.
succession-and-lapseSuccession, Lapse and Chain of Title3 findings

Involuntary movement of control on death, dissolution, abandonment or lapse, and the reconstruction of the full history of a holding.

succession-dissolution-lapse

Succession, dissolution and lapse

Control can move without any act of the holder: on death, on dissolution of a legal person, on expiry of a term, on abandonment, or by operation of law to the state. CRPD Article 12(5) requires equal rights to own and inherit property and protection against arbitrary deprivation, which constrains how a lapse may be declared. An interim state — estate in administration, holder deceased but successor undetermined — must be representable, because forcing an immediate successor invents a fact.

Questions
  1. What event opened the succession or lapse — death, dissolution, term expiry, abandonment or operation of law?event
    Expected answer
    • trigger event type
    • trigger event timestamp (RFC 3339)
    • evidencing source reference
  2. Who, if anyone, controls the object between the trigger event and the vesting of a successor?state
    Expected answer
    • interim state code (in-administration | vacant | held-by-administrator)
    • administrator or personal representative reference
    • interim powers and limits
  3. By what rule does control vest in the successor, and when does vesting take effect relative to the trigger?process
    Expected answer
    • vesting rule (testamentary | intestate | contractual | statutory | escheat)
    • vesting effective timestamp
    • retroactivity treatment
  4. Before declaring abandonment or lapse, what diligent search was performed and over what period?evidence
    Expected answer
    • search steps performed
    • search period start and end
    • search outcome
    • declaring authority
Artifacts
  • Succession noticeThe record opening a succession or lapse, naming the trigger event, the interim controller and the vesting rule to be applied.
chain-of-title-reconstruction

Chain of title reconstruction

dcterms:provenance defines exactly this: a statement of changes in ownership and custody significant for authenticity, integrity and interpretation. An agent must be able to reconstruct, for any past instant, who held the object and under what basis, and to detect where the chain has a gap, an overlap or an unevidenced link — because a chain that silently interpolates is worse than one that admits a hole.

Questions
  1. Who held this object in a given modality at a specified past instant, and on what basis?temporal
    Expected answer
    • as-of timestamp (RFC 3339)
    • holder set at that instant
    • basis and source at that instant
    • reconstruction confidence
  2. Where does the chain have gaps, overlaps or links with no evidencing source?quality
    Expected answer
    • gap intervals
    • overlap intervals
    • unevidenced link references
    • completeness score
  3. What is the earliest recorded control position, and is it a genuine origin or merely the register's own start date?provenance
    Expected answer
    • root record reference
    • root type (original acquisition | register inception | migrated-in)
    • pre-register evidence if any
  4. For links inherited from a predecessor register or migration, what mapping and loss occurred?interoperability
    Expected answer
    • source system reference
    • migration mapping notes
    • fields lost or approximated
    • migration timestamp
Artifacts
  • Chain of title extractThe ordered transfer history of one object with bases, effective and recorded times, and explicit gap and overlap markers; omits the parties' unrelated holdings.
involuntary-deprivation-and-lapse-events

Involuntary and abandonment events

FAO VGGT requires States to safeguard legitimate tenure rights against arbitrary loss including forced evictions, and treats expropriation among transfers and other changes. HCCH Article 11 ring-fences trust assets from the trustee's insolvency; Article 15(e)–(f) preserves insolvency-creditor protection and good-faith third-party rules, which may defeat a trust or a transfer. FATF notes misuse of corporate vehicles for sanctions evasion; a freeze or confiscation is an exceptional restriction or transfer effect. Abandonment, bona vacantia, escheat and adverse possession are widely attested in domestic law but lack a single global primary instrument in this source set; they are recorded only as jurisdiction-tagged exceptional events, not as universal classes. Dispute procedure itself belongs to the courts model; this finding stores the resulting effect.

Questions
  1. What exceptional event affected which holdings, what is the effect on title, and which authority ordered it?event
    Expected answer
    • event-class: class
    • affected-ownership-record-ids: holdings
    • effect: effect
    • authority-id: authority
  2. In which jurisdiction is this event class recognised, and is it a universal mixin class or a tagged local doctrine?exception
    Expected answer
    • jurisdiction: jurisdiction
    • universal-class-flag: universality
  3. Does a good-faith third-party or insolvency-creditor rule under HCCH Article 15 defeat or qualify this holding or this trust?constraint
    Expected answer
    • art15-hit: whether Art 15(e) or (f) applies
    • qualification: how title is qualified
Artifacts
  • Exceptional effect recordJurisdiction-tagged record of an involuntary or abandonment effect on title, pointing at the ordering instrument without storing court procedure.
assuranceState, Time, Evidence and Contestation3 layers

The lifecycle states of a control assertion, its temporal semantics, the evidence and assurance behind it, and the handling of competing claims.

state-and-timeState and Temporal Semantics2 findings

Lifecycle states of a control assertion and the separation of event, effective, observation and record time.

control-record-lifecycle-states

Control record lifecycle states

A control assertion moves through determinate states — proposed, pending conditions, effective, suspended, disputed, superseded, terminated — with defined transitions and defined authorities for each transition. LADM's versioned-object foundation means a superseded state remains addressable rather than being erased. The state must be explicit so that an agent never treats a pending or disputed assertion as an operative one.

Questions
  1. What is the current state of this control assertion, and which transition produced it?state
    Expected answer
    • state code
    • transition event reference
    • transition timestamp (RFC 3339)
    • transitioning authority
  2. Which transitions are permitted from the current state, and who is authorised to make each?lifecycle
    Expected answer
    • permitted transition list
    • authorised role per transition
    • required preconditions per transition
  3. Which states are operative for reliance purposes, and which must a relying agent refuse to act on?decision
    Expected answer
    • operative state set
    • non-operative state set
    • handling instruction for non-operative states
  4. What suspends a control assertion without terminating it, and what restores it?exception
    Expected answer
    • suspension trigger
    • suspension authority
    • restoration condition
    • effect on subsisting mandates
Artifacts
  • State transition logThe append-only sequence of state transitions for a control assertion, each with timestamp, actor, authority and reason.
temporal-semantics

Temporal semantics of control

Four times matter and must not be merged: when the underlying event occurred, from when the control is effective, when the register observed or ingested it, and when the record was written. LADM's versioned objects carry lifespan bounds for exactly this reason. All are RFC 3339 with seconds and an explicit offset or Z, because a local time without offset makes cross-jurisdiction ordering of competing dispositions undecidable.

Questions
  1. Over what interval is this control assertion effective, and is the end open or determinate?temporal
    Expected answer
    • effective from (RFC 3339)
    • effective to (RFC 3339 or open)
    • interval boundary inclusivity
  2. When was this fact observed or ingested, and how far did it lag the event it records?temporal
    Expected answer
    • observation/ingestion timestamp (RFC 3339)
    • event timestamp (RFC 3339)
    • lag duration
  3. Does every recorded timestamp carry seconds and an explicit UTC offset or Z, and what is the local civil-time context where it matters?validation
    Expected answer
    • offset presence check result
    • originating time zone identifier
    • civil-date interpretation note
  4. Does this record change the past, and if so what was believed true before the retroactive change?provenance
    Expected answer
    • retroactivity flag
    • prior belief snapshot reference
    • reason for retroactive change
evidence-and-assuranceEvidence and Assurance2 findings

What backs a control assertion and how much weight an agent may place on it.

evidentiary-sources-and-attestation

Evidentiary sources and attestation

LADM binds every core class to a source; verifiable credentials give a machine-checkable attestation shape and make explicit that the party presenting an attestation is often not its subject. A control record must therefore distinguish the issuer of an attestation, the subject it concerns, the party presenting it, and the integrity data that lets a verifier check it was not altered.

Questions
  1. Who issued each evidencing attestation, about which subject, and who presented it to the register?evidence
    Expected answer
    • issuer reference
    • subject reference
    • presenter reference
    • issuer-subject-presenter divergence note
  2. What integrity data proves the evidencing source has not been altered since issuance?security
    Expected answer
    • digest algorithm and value
    • signature or proof reference
    • verification result and timestamp
  3. Is the evidence independent of the party it benefits, or self-asserted?quality
    Expected answer
    • evidence independence class (authority-issued | third-party | counter-signed | self-asserted)
    • corroborating sources
    • weight assigned
  4. Does the evidencing source itself expire or require renewal, and what happens to the control record when it does?lifecycle
    Expected answer
    • source validity period
    • renewal obligation
    • downgrade rule on expiry
Artifacts
  • Attestation of controlA verifiable, independently checkable statement by an authorised issuer that a named party holds control of a named object in a named modality over a stated interval.
assurance-and-currency

Assurance level and currency

AMLR's requirement that beneficial ownership information be adequate, accurate and up to date generalises: every control assertion needs a stated assurance level, a last-verified time, and a staleness policy. VGGT's recognition of informal and customary tenure means low assurance must be an honest recorded value, not grounds for treating a holding as non-existent.

Questions
  1. What assurance level does this control assertion carry, and what evidence and verification method produced it?quality
    Expected answer
    • assurance level code
    • verification method used
    • verifying party
    • assurance rationale
  2. When was the assertion last verified, and by what date does it become stale for reliance purposes?temporal
    Expected answer
    • last verified timestamp (RFC 3339)
    • staleness threshold
    • current staleness status
  3. For informal, customary or unregistered holdings, how is low assurance recorded without implying the holding is invalid?exception
    Expected answer
    • informal-holding marker
    • recognition status
    • explicit non-invalidity statement
Artifacts
  • Assurance review reportThe periodic report over a population of control records showing assurance levels, staleness distribution, unverified assertions and remediation actions.
contestationContestation1 findings

Competing claims over the same object and their resolution status.

competing-claims-and-dispute-status

Competing claims and dispute status

Because a register records assertions rather than facts, two irreconcilable claims can coexist. VGGT's recognition of overlapping customary and formal tenure makes this normal rather than exceptional. The model must hold both claims, mark the object as contested, apply a stated priority rule where one exists, and ingest an outcome reference from the dispute model without itself adjudicating.

Questions
  1. Which claims over this object are irreconcilable, and in what respect do they conflict?relationship
    Expected answer
    • competing claim references
    • conflict dimension (holder | modality | extent | share | priority)
    • overlap description
  2. Is there a stated priority rule between the competing claims, and what does it yield?constraint
    Expected answer
    • priority rule reference
    • rule outcome
    • provisional preferred claim
    • rule-absent flag
  3. While contested, which operations on the object are frozen, permitted or permitted only with notice?constraint
    Expected answer
    • frozen operation set
    • permitted operation set
    • notice obligations to counterparties
  4. How is a resolution ingested from the dispute forum, and what does it change in the control record?process
    Expected answer
    • outcome reference and forum
    • resulting record changes
    • effective date of the outcome
    • residual appeal status
Artifacts
  • Contested claim noticeA public or counterparty-facing notice that control of a named object is contested, stating what is frozen and where the dispute is pending, without stating who is right.
register-governanceGovernance of the Control Register2 layers

The authority that maintains control records, who may read them, what must be retained or erased, and how the model aligns to external standards.

register-authorityRegister Authority and Access2 findings

Who maintains the register, what its recording confers, and who may see what.

register-authority-and-competence

Register authority and competence

A control register has a maintaining authority whose competence is bounded by object class, jurisdiction and modality. NIST's information owner is defined by statutory or operational authority; LADM presumes a land administration authority. Where an object falls outside the register's competence, its records are at best evidentiary, and the register must say so rather than presenting them as authoritative.

Questions
  1. Which authority maintains this register, over which object classes, modalities and territory?authority
    Expected answer
    • maintaining authority reference
    • competence scope (object classes, modalities, territory)
    • instrument conferring competence
  2. What does an entry in this register confer — constitutive effect, a rebuttable presumption, or evidence only?authority
    Expected answer
    • register effect code
    • rebuttal procedure
    • reliance guidance for third parties
  3. How are records outside the register's competence marked, and what may an agent infer from them?exception
    Expected answer
    • out-of-competence marker
    • inference limitation statement
    • authoritative register pointer where known
  4. Where two registers claim competence over the same object, which prevails and how is the conflict surfaced?interoperability
    Expected answer
    • overlapping register references
    • precedence rule or absence thereof
    • conflict disclosure on extracts
Artifacts
  • Register charterThe constitutional statement of the register: maintaining authority, competence scope, recording effect, correction procedure and appeal route.
control-data-access-and-disclosure

Control data access and disclosure

Ownership data is not inherently public. The CJEU held that giving the general public access to beneficial ownership information is a serious and disproportionate interference with Charter Articles 7 and 8, since a legitimate-interest regime achieves comparable results. The register must therefore default to restricted access, define disclosure tiers, apply a legitimate-interest test, and log privileged reads — while still supporting the minimal current-holder extract a counterparty genuinely needs.

Questions
  1. Which audience tiers may read which layers of the control record, and what is the default for an unclassified requester?access
    Expected answer
    • audience tier definitions
    • readable layers per tier
    • default deny statement
  2. How is a requester's legitimate interest established and recorded before privileged disclosure?privacy
    Expected answer
    • legitimate interest test criteria
    • requester declaration
    • assessment outcome and assessor
  3. What is the minimum disclosure that satisfies a given purpose — current holder only, or the full record?privacy
    Expected answer
    • purpose code
    • minimal projection for that purpose
    • fields withheld
  4. Which reads are logged, with what detail, and for how long is the read log kept?security
    Expected answer
    • logged read categories
    • log fields
    • log retention period
    • log access rules
Artifacts
  • Disclosure policyThe published mapping from audience tier and purpose to permitted projection over control records, including the legitimate-interest test and the redaction rules for public projections.
continuityRetention, Deletion and Interoperability2 findings

How long control history is kept against erasure and portability rights, and how the model maps onto external standards without overclaiming conformance.

retention-archival-and-deletion

Retention, archival and deletion

Control history and personal-data rights pull in opposite directions. dcterms:provenance treats the ownership and custody chain as essential to authenticity, and a chain with holes cannot support reliance; GDPR nonetheless grants rectification and, in defined circumstances, erasure. The resolution is explicit: define which elements are permanent register content, which are erasable identifying attributes held by reference in the party model, and use tombstoning rather than physical deletion of links.

Questions
  1. How long is each class of control record retained, and what legal or operational basis sets that period?retention
    Expected answer
    • record class
    • retention period
    • basis for the period
    • disposition action at end of period
  2. When a party exercises an erasure or rectification right, which elements can be removed and which must survive as an anonymised or tombstoned link?retention
    Expected answer
    • erasable element set
    • non-erasable element set with justification
    • tombstone representation
    • residual linkage risk
  3. How is chain integrity preserved when an intermediate record is redacted or tombstoned?quality
    Expected answer
    • integrity preservation method
    • gap marker semantics
    • effect on reconstruction confidence
  4. On decommissioning of the register, who takes custody of the historical control records and under what terms?lifecycle
    Expected answer
    • successor custodian reference
    • custody transfer instrument
    • continued access terms
    • transfer timestamp
Artifacts
  • Retention and disposition scheduleThe schedule mapping each control record class to its retention period, basis, permitted redactions and end-of-life disposition.
interoperability-and-alignment

Interoperability and standards alignment

The model aligns with, rather than conforms to, external standards: LADM's party/RRR/administrative-unit pattern, PROV's attribution and delegation, ODRL's assigner/assignee and duty, CID's controller and capability relationships, and dcterms' rightsHolder and provenance. Each alignment is partial and each has a known conflict; claiming conformance without a tested profile and evidence would be false. Portability under GDPR Article 20 also requires an export shape that a receiving system can actually ingest.

Questions
  1. For each external standard, which elements of this model map, which map only partially, and which have no counterpart?interoperability
    Expected answer
    • target standard and version
    • mapped element pairs
    • partial mappings with loss notes
    • unmapped elements
  2. Where does an external standard's semantics conflict with this model's, and which prevails in an export?interoperability
    Expected answer
    • conflict description
    • resolution rule
    • warning emitted on export
  3. Is a conformance claim to any external standard being made, and what test evidence supports it?validation
    Expected answer
    • conformance claim status (alignment-only | profiled | tested-conformant)
    • test suite and results reference
    • date of last test
  4. What export shape lets a holder move their control records to another system in a structured, machine-readable form?interoperability
    Expected answer
    • export format and schema reference
    • included and excluded elements
    • receiving-system requirements
Artifacts
  • Alignment crosswalkElement-by-element mapping table between this model and LADM, PROV-O, ODRL, CID/DID, VC and DCMI terms, with strength, loss and conflict annotations per pair.

Publication holds

  • Source and live-version verification is not complete and must be retained as a hold: Grok's CRPD citation resolves to a generic OHCHR instruments page rather than Article 12, its LADM support is a FIG co-editor paper rather than the ISO text, Claude's UCC Article 12 citation is a Uniform Law Commission community page rather than the act text, and Claude's DID v1.1 is a Candidate Recommendation snapshot whose alignment is provisional.
  • Multi-profile domain validation has not been performed by either provider. Before publication the mixin must be exercised against at least a land-parcel profile, an electronic-transferable-record profile, a corporate-vehicle/beneficial-ownership profile and a personal-data profile, since its defaults are calibrated to EU law and would misfire in open-register jurisdictions.
  • Normative clause text of ISO 19152-1:2024, ISO/IEC 27002:2022 and ISO 19115-1 was never read directly by either provider. Every attribute-level alignment claim to LADM, control 5.9 and CI_RoleCode must be labelled unverified in the draft, and no conformance claim may be made.
  • The imported HCCH trust material (Articles 2, 3, 8, 11, 13, 15) and FATF Recommendation 24/25 material were read at page and guidance level. Clause-level confirmation against the primary instruments is required before these claims are cited in the merged draft.
  • The two additions that touch legal effect — governing-law-and-situs and involuntary-deprivation-and-lapse-events — must be re-read against the base out_of_scope line stating that this model records a claimed basis and its evidence rather than its legal validity, to confirm the merged text does not slide into asserting recognition or adjudicating deprivation.
  • Merged source de-duplication is unverified: VGGT and CRPD Article 12 appear in both packs under different IDs and URLs, and MLETR appears as a landing page in one and a PDF in the other. The synthesizer's source merge must be reviewed before the draft is published.

Deferred research

  • Tenure-form typology from VGGT (public, private, communal, indigenous, customary, informal, mixed) as an axis orthogonal to control modality — determine whether it belongs as an added dimension inside control-modality-classification or as a distinct finding, and how it interacts with the non-defaulting modality rule.
  • FATF concealment typology as enrichment of legal-versus-beneficial-holder: nominee shareholders and directors, layered legal persons, bearer-share immobilisation, and control through other means beyond any local percentage threshold.
  • ISO 19115-1 CI_RoleCode alignment, including confirmation from the live TC 211 codelist that no 'steward' code exists, so the model does not emit a non-canonical role code in exports.
  • Valuation and consideration sibling: Claude's checklist records this as its only outright gap, with ISO 19152-4 named as the untested alignment target and no registered sibling model.
  • Archival custody transfer anchor: OAIS (ISO 14721 / CCSDS 650.0-M-3) could not be retrieved, so the custody and successor-custodian elements currently rest only on DCMI and GDPR.
  • Whether an autonomous software agent or a DAO can hold rather than merely exercise control — both providers leave legal personality for non-human holders unresolved, and no consulted source settles it.
  • Placement of a transfer-watch / legitimate-interest notification capability: whether it belongs to this control mixin or to a sibling eventing or access model, given that the mixin already excludes runtime authorization and audit.